Type something to search...

Security & data handling

Your data never leaves your perimeter.

Most vendor-security risk comes from sending your data to a SaaS. We remove that risk at the root: the evaluation runs inside your own cloud, on your keys, and we work against your data where it already lives.

01 The posture

In your environment, on your keys.

Runs in your VPC (your own cloud)

The default deployment is inside your own cloud account or on-prem. The evaluation harness, your corpus, and your traces stay in your environment. Nothing is copied to us to run it.

Judge models use your keys

When an evaluation calls a judge model, it uses your provider keys and your endpoints. We do not proxy your data through our own inference.

PII handled at the boundary

Personal data is redacted or tokenised before anything is scored, and never leaves your perimeter. For regulated buyers this is the first question, so it is answered by design, not by policy.

You own your corpus

You keep a perpetual, irrevocable licence to the corpus we build from your data, and you own your raw source data outright. We retain the framework, tooling, and methodology, never your data.

02 The contract

Written down before the first serious call.

Data processing agreement

A DPA covering DPDP (India) and GDPR obligations, with named sub-processors, retention and deletion terms, and PII minimisation.

Liability cap

Capped at fees paid, with carve-outs for data breach and IP infringement, the standard, defensible posture for a services engagement.

Access is scoped and temporary

Any access to your environment is least-privilege, time-boxed to the engagement, and revoked on completion. There is no standing connection to your systems.

Straight answers

Are you SOC 2 certified?

Not yet. Because evaluations run inside your own VPC and your data never reaches our servers, the SaaS data-exfiltration surface that SOC 2 mainly addresses does not exist for the delivery model. For enterprise engagements that require it, we will scope a formal SOC 2 or client-specific security review; a certification effort is on the roadmap as the practice grows.

Where does our data live during an evaluation?

In your environment only. The corpus, the traces, and the judge calls all stay inside your VPC or on-prem deployment. We work against it there rather than pulling it out.

Can we run this fully air-gapped?

Yes, where your environment supports it. The harness is designed to run without any callback to us, using only the model endpoints and keys you provide.

Who can see the results?

You do. Results, raw votes, and the audit trail live in your environment. We deliver the decision table, frontier, and evidence pack; we do not retain your data to produce them.

Have a security review coming?

Bring us your questionnaire. Because the work runs in your environment, most of it answers itself, and we will walk your team through the rest.